Topic: ransomware deployment
-
Ransomware Strikes Most After Hours
Attackers strategically time their most damaging actions, like ransomware encryption and data theft, for outside standard business hours when defenses are weakest, occurring in 88% and 79% of incidents respectively. Identity theft, through stolen credentials or phishing, is the primary entry poin...
Read More » -
Romania’s land registry hacked, stolen data reportedly for sale
Romania's ANCPI experienced a severe operational breakdown of its e-Terra land registry system on July 14, initially called a technical incident but now officially classified as a cyber attack, with the agency stating that data has not been compromised. The outage has halted property transactions...
Read More » -
Scattered Spider Now Targets VMware vSphere in New Attacks
A cybercrime group, Scattered Spider (UNC3944), is targeting VMware vSphere environments in critical industries like retail, airlines, and insurance using social engineering and hypervisor-level exploitation. The attackers use phone-based impersonation to gain credentials, escalate access to vCen...
Read More » -
Microsoft Ties Medusa Ransomware to Zero-Day Exploits
Microsoft reports that the China-based threat actor Storm-1175 has escalated its tactics by incorporating both n-day and zero-day exploits into its campaigns, which deploy Medusa ransomware. The group's use of unpatched zero-days alongside recently patched n-day vulnerabilities enables high-veloc...
Read More » -
Gootloader Malware Returns With New Evasion Tactics
The Gootloader malware has returned with enhanced SEO poisoning tactics, using fake legal document websites to trick users into downloading malicious .js files that deploy additional malware like Cobalt Strike and backdoors. New evasion techniques include a custom web font that disguises filename...
Read More » -
Jaguar Land Rover Confirms Data Breach After Cyberattack
Jaguar Land Rover confirmed a significant data breach and system disruption from a recent cyberattack, leading to temporary shutdowns and affecting its global operations. The company is working with cybersecurity experts to restore systems and has acknowledged that some data was stolen, though sp...
Read More » -
Scattered Spider Targets VMware ESXi in Latest Hacking Wave
A hacking group, Scattered Spider, is targeting VMware ESXi hypervisors via social engineering, compromising U.S. corporations by impersonating employees to gain network access. The attackers exploit privileged accounts to control VMware vCenter, enabling SSH on ESXi hosts and executing disk-swap...
Read More » -
How social engineering keeps breaching the service desk
Social engineering attacks targeting corporate service desks remain highly effective, as demonstrated by 2025 breaches at M&S, Co-op, Harrods, and Carnival Corporation, where attackers impersonated employees or IT staff to reset credentials and gain system access. Service desks are attractive tar...
Read More » -
Pay2Key Ransomware Group Linked to Iran Returns
The ransomware group Pay2Key, with suspected ties to Iran, has re-emerged with significantly upgraded technical capabilities, and its activity appears to accelerate during periods of geopolitical tension, such as recent U.S.-Iran tensions. In a recent attack on a U.S. healthcare provider, the gro...
Read More » -
Iran-Targeting Malware Infects Open Source Software
A new hacking group, TeamPCP, is conducting a sophisticated campaign using a self-spreading worm and a data wiper, primarily targeting systems in Iran and exploiting cloud platforms for malicious activities like data theft and ransomware. The group escalated its operations by executing a supply-c...
Read More » -
Clorox Sues Vendor Over $380M Hack Due to Password Mishandling
Cyberattacks frequently target human vulnerabilities, as seen in Clorox's $380M breach caused by lax authentication practices by its IT vendor, Cognizant. Hackers easily bypassed security by impersonating employees, obtaining unauthorized access through Cognizant's unverified password resets and ...
Read More » -
U.S. Insurance Firms Now Prime Targets for Cyber Hackers
Cybercriminals, particularly the hacking group Scattered Spider, are increasingly targeting U.S. insurance companies, shifting from previous attacks on U.K. retail organizations. Recent breaches at Philadelphia Insurance Companies and Erie Insurance highlight the group's tactics, including social...
Read More » -
Decade-Old EnCase Driver Still Defeats Modern EDR
A new malware strain can disable modern EDR solutions by exploiting an outdated, revoked-but-still-loadable kernel driver from old EnCase forensics software. The attack uses a BYOVD technique, where the legitimate driver, once loaded, allows user-mode processes to kill critical security processes...
Read More » -
Chinese Hackers Exploit Critical SharePoint 'ToolShell' Flaws
Chinese-linked hacking groups (Linen Typhoon, Violet Typhoon, Storm-2603) are exploiting critical Microsoft SharePoint vulnerabilities (CVE-2025-53770, CVE-2025-53771) to steal data or deploy ransomware. Linen Typhoon targets government and defense sectors, while Violet Typhoon focuses on intelle...
Read More » -
Dangerous VSCode Extensions Steal Crypto on OpenVSX
Malicious extensions in the VSCode ecosystem, such as C++ Playground and HTTP Format, have been downloaded thousands of times and are designed to steal cryptocurrency or create backdoors, with the threat actor TigerJack repeatedly uploading them under new names to evade detection. These extension...
Read More » -
Hackers Still Exploit WinRAR Flaw, Mandiant Reports
A critical WinRAR vulnerability (CVE-2025-8088) is being actively exploited by state-sponsored and criminal hackers, despite a patch being available for over six months. The exploit hides malicious payloads within archive files to execute automatically upon user login, with attacks linked to a si...
Read More »